{"id":"AZL-95604","summary":"CVE-2026-70622 affecting package kata-containers 3.32.0.kata0-2","details":"tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-controlled directory. When a privileged process archives an untrusted directory, the function follows symlinks without verifying that resolved targets remain within the source root, causing out-of-bounds files to be included in the archive as regular files and disclosed to the attacker.","modified":"2026-08-29T05:27:27Z","published":"2026-08-10T18:18:50Z","upstream":["CVE-2026-70622"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70622"}],"affected":[{"package":{"name":"kata-containers","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kata-containers"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.32.0.kata0-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95604.json"}}],"schema_version":"1.9.0"}